Assess Vendor Risk and Due Diligence
Discover how to assess vendor risk and complete due diligence using Sprinto’s scoring model and AI-powered analysis.
Sprinto enables you to assess each vendor’s risk profile through configurable risk scoring and guided due diligence workflows. These tools help you determine whether a vendor poses a compliance threat and ensure that appropriate controls are in place.
You can score vendor risk, perform due diligence manually or with Sprinto AI, and maintain audit-ready documentation for all high-risk vendors.
1. Score Vendor Risk
Each vendor is automatically assigned a risk score based on Sprinto’s predefined risk factors. You can customise this scoring logic under the Configuration tab.
Risk scoring factors include:
Type of data shared (e.g., cardholder data, credentials, customer PII)
Access to company systems (e.g., databases, production environments)
Operational impact (e.g., business-critical, internal tools)
Steps to score risk:
Go to All vendors and click a vendor name.
Open the Risk score tab.

For each risk factor, click Add value or Edit.
Select appropriate responses from the dropdown.
Click Add risk factor values after completing all required fields.
Choose to:
Use Sprinto’s auto-computed risk level, or
Override and define your own risk level

2. Perform Due Diligence
Due diligence is mandatory for vendors classified as High risk. Sprinto supports manual method.
Steps:
Navigate to the vendor profile and open the Due diligence tab.
Click perform due diligence.

Upload relevant security documents (for example, SOC 2 reports, ISO certificates and so on).
Add notes and findings.
Under the Review vendor documents and complete due diligence section, you can select eother:
Vendor meets necessary security requirements.
Manually review vendor documents and add notes.
If you select the second option, you will need to add additional notes for your manual review.
Click Complete due diligence to finish the process.

3. Upload or Request Security Documents
You can upload security documents manually or request them directly from the vendor.
To upload manually:
Go to the Documents & links tab in the vendor profile.
Click Add docs/links.

Choose a document/link type.
Select the check box you wish to add:
Attach a file
Add a URL
Click Add another document/link if you wish to add additional documents/links.
Click Save.

To request from a vendor:
Click Request docs from vendo in the same tab.

Select the check boxes for the documents to you want to request.
Enter the vendor’s email address.
Enter the recipient's email address.
Select required document types.
You can also add a subject, header and a message to the vendor.
Click Preview & send request.

Last updated